Measurement needs a source and an outcome. It does not need a person. The system we build never has to hold a patient’s name, condition, or record, so there is nothing sensitive in it to protect.
The limits, stated plainly
- There is no HIPAA certification for agencies or for software, so we do not claim one.
- No vendor can make a practice compliant.
- We are not attorneys, and nothing we publish is legal advice.
What we can do is build the parts we control so they do not put you at risk, publish exactly how we handle it, and give your privacy officer or counsel everything they need to check it.
What we engineer
Attribution
We record where an inquiry came from and whether it became an appointment. Nothing else is needed for that, so nothing else is collected.
Portals
Your marketing pages can be measured. Your patient portal is a different building, and we do not put marketing code in it.
Audiences
We do not build advertising audiences from people who read about a condition, and we do not upload patient lists to any platform.
Calls
We record where an inquiry came from and whether it booked, never who sent it.
Written record
Every tracking script on your site is inventoried in writing, with what it sends and where it goes, so your privacy officer can review it in an afternoon.
The decisions that are yours stay yours. Where one is, we say so and give you the facts, and anything touching patient data should be reviewed by your own counsel or privacy officer.